CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-37744
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_pci_remove() Kmemleak reported this error: unreferenced object 0xffff1c165cec3060 (size …

May 1, 2025
CVE-2025-37743
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid memory leak while enabling statistics Driver uses monitor destination rings for extended …

May 1, 2025
CVE-2025-37742
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: jfs: Fix uninit-value access of imap allocated in the diMount() function syzbot reports that hex_dump_to_buffer …

May 1, 2025
CVE-2025-37741
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: jfs: Prevent copying of nlink with value 0 from disk inode syzbot report a deadlock …

May 1, 2025
CVE-2025-37740
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: jfs: add sanity check for agwidth in dbMount The width in dmapctl of the AG …

May 1, 2025
CVE-2025-23163
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: vlan: don't propagate flags on open With the device instance lock, there is now …

May 1, 2025
CVE-2025-23162
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Don't try to trigger a full GT reset if VF VFs don't have access …

May 1, 2025
CVE-2025-23161
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: vmd: Make vmd_dev::cfg_lock a raw_spinlock_t type The access to the PCI config space via …

May 1, 2025
CVE-2025-23160
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization …

May 1, 2025
CVE-2025-23159
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add a check to handle OOB in sfr region sfr->buf_size is in …

May 1, 2025
CVE-2025-23155
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Fix accessing freed irq affinity_hint In stmmac_request_irq_multi_msi(), a pointer to the stack variable …

May 1, 2025
CVE-2025-23154
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/net: fix io_req_post_cqe abuse by send bundle [ 114.987980][ T5313] WARNING: CPU: 6 PID: 5313 …

May 1, 2025
CVE-2025-23153
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm/crc-t10dif: fix use of out-of-scope array in crc_t10dif_arch() Fix a silly bug where an array …

May 1, 2025
CVE-2025-23152
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64/crc-t10dif: fix use of out-of-scope array in crc_t10dif_arch() Fix a silly bug where an array …

May 1, 2025
CVE-2025-23151
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Fix race between unprepare and queue_buf A client driver may use mhi_unprepare_from_transfer() …

May 1, 2025
CVE-2025-23150
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix off-by-one error in do_split Syzkaller detected a use-after-free issue in ext4_insert_dentry that was …

May 1, 2025
CVE-2025-23149
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tpm: do not start chip while suspended Checking TPM_CHIP_FLAG_SUSPENDED after the call to tpm_find_get_ops() can …

May 1, 2025
CVE-2025-23148
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: samsung: exynos-chipid: Add NULL pointer check in exynos_chipid_probe() soc_dev_attr->revision could be NULL, thus, a …

May 1, 2025
CVE-2025-23147
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i3c: Add NULL pointer check in i3c_master_queue_ibi() The I3C master driver may receive an IBI …

May 1, 2025
CVE-2025-23146
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mfd: ene-kb3930: Fix a potential NULL pointer dereference The off_gpios could be NULL. Add missing …

May 1, 2025
CVE-2025-23145
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix NULL pointer in can_accept_new_subflow When testing valkey benchmark tool with MPTCP, the kernel …

May 1, 2025
CVE-2025-23144
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: backlight: led_bl: Hold led_access lock when calling led_sysfs_disable() Lockdep detects the following issue on led-backlight …

May 1, 2025
CVE-2025-23143
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. When I ran the repro [0] and waited …

May 1, 2025
CVE-2025-23141
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses Acquire a lock on …

May 1, 2025
CVE-2025-23140
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error After devm_request_irq() fails with error …

May 1, 2025
CVE-2023-46669
6.2 MEDIUM

Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint …

May 1, 2025
CVE-2025-4163
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Land Record System 1.0. This issue affects some unknown processing of the file …

May 1, 2025
CVE-2025-3890
6.4 MEDIUM

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' shortcode in all versions up to, and …

May 1, 2025
CVE-2025-3889
5.3 MEDIUM

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 via the …

May 1, 2025
CVE-2025-3874
6.5 MEDIUM

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 due to …

May 1, 2025
CVE-2025-1529
6.4 MEDIUM

The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded lottie files in all versions up to, and including, 3.5.3 due …

May 1, 2025
CVE-2025-4157
6.3 MEDIUM

A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/booking-details.php. The …

May 1, 2025
CVE-2025-4156
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-image.php. The …

May 1, 2025
CVE-2025-4155
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file /admin/edit-boat.php. The …

May 1, 2025
CVE-2025-4154
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this issue is some unknown functionality of …

May 1, 2025
CVE-2025-4100
6.4 MEDIUM

The Nautic Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'np_marinetraffic_map' shortcode in all versions up to, and including, 2.0 …

May 1, 2025
CVE-2025-47153
6.5 MEDIUM

Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-2_i386.deb for Debian GNU/Linux, have an inconsistent …

May 1, 2025
CVE-2025-3521
6.4 MEDIUM

The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

May 1, 2025
CVE-2025-3504
4.8 MEDIUM

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as …

May 1, 2025
CVE-2025-3503
4.8 MEDIUM

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as …

May 1, 2025
CVE-2025-3502
4.8 MEDIUM

The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as …

May 1, 2025
CVE-2024-13381
4.8 MEDIUM

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 1, 2025
CVE-2025-4099
6.4 MEDIUM

The List Children plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list_children' shortcode in all versions up to, and including, 2.1 …

May 1, 2025
CVE-2024-13845
5.5 MEDIUM

The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.0 via the 'process_feed' method …

May 1, 2025
CVE-2025-2168
4.3 MEDIUM

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to …

May 1, 2025
CVE-2025-4143
6.1 MEDIUM

The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on the allowed list of …

May 1, 2025
CVE-2024-30146
4.1 MEDIUM

Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.

Apr 30, 2025
CVE-2024-30145
6.5 MEDIUM

Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.

Apr 30, 2025
CVE-2024-30115
6.3 MEDIUM

Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

Apr 30, 2025
CVE-2023-45721
5.3 MEDIUM

Insufficient default configuration in HCL Leap allows anonymous access to directory information.

Apr 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.